Live data from Hacker News

Should All Web Traffic Be Encrypted?

codinghorror.com

101–110 of 136 posts

Re: Should All Web Traffic Be Encrypted?

#101
post #90

Just Tuesaday, I sent an email around the company discussing SSL vulnerabilities, how they impact our product, and ways we can mitigate that. I've pulled out the parts specific to our product, but the rest may be interesting. I would love feedback on things I may have missed. FWIW, it doesn't instill great confidence in SSL, but it isn't completely horrible. ------------------------ 1. It is possible to pretend to be…

How is Convergence different from the Perspectives add-on[1]? I ask because I honestly don't see any significant advantage to one over the other. [1] https://addons.mozilla.org/en-US/firefox/addon/perspectives/

Convergence has a proxy system built in so you connect to notaries via other notaries. It's a rather rudimentary attempt at offering privacy to the user looking up the certificate. It (rightly or wrongly) works on the assumption that people running notaries wont collude.

Re: Should All Web Traffic Be Encrypted?

#102

Earlier quoted context omitted.

If HTTP referrers never existed, the web would still be huge and would still be full of amazing content. Why should we care about retaining referrers? I think the only reason that people dislike the idea of losing them, is because they've got used to them being there. I don't particularly like the fact that sites which I click through to can see where I'm coming from, or what I was searching for, so I've installed a…

Inertia shouldn't stop us doing something. Where a visitor comes from is very valuable (not just monetarily), and I don't think it really infringes on privacy.

It absolutely does infringe on privacy. The only thing that is up for question is by how much and if the benefits outweigh the drawbacks. People who benefit from them existing are obviously going to have a different view point to everyone else (on average).

I don't think that referrers should ever have been a part of the protocol and I don't think that the commercial value of them existing should have any influence on whether or not HTTP continues to include them. Unfortunately, both Google and Microsoft benefit financially from the existence of referrer headers, so I don't see them going anywhere in Chrome or IE at least.

Re: Should All Web Traffic Be Encrypted?

#103

Wouldn't it provide good additional security if there would be a possibility to define those HTTPS Pins [1] in the DNS, in TXT recods? This would be fairly lightweight way for me to say which CA(s) I use for a particular domain. [1] http://www.imperialviolet.org/2011/05/04/pinning.html

With second thought this does not make sense.

False certificates would be only problem in man-in-the-middle attacks of if the attacker can alter information in dns. In both cases the attacker could also fake the information about valid ca's.

Re: Should All Web Traffic Be Encrypted?

#104
post #55

One item that this (excellent) blog post does not adress is what to do about referer information which is generally not passed along when clicking on links on sites being browsed over SSL. In order to "get credit" for all of the traffic that they send everywhere twitter had to develop a fairly elaborate system of redirections (built into t.co) to make sure that clicks from twitter.com ended up being sent out to the r…

If HTTP referrers never existed, the web would still be huge and would still be full of amazing content. Why should we care about retaining referrers? I think the only reason that people dislike the idea of losing them, is because they've got used to them being there. I don't particularly like the fact that sites which I click through to can see where I'm coming from, or what I was searching for, so I've installed a…

Referrer information allows website owners to see who is linking to their site. It's like a private, reverse form of tags

Re: Should All Web Traffic Be Encrypted?

#105
post #90

Just Tuesaday, I sent an email around the company discussing SSL vulnerabilities, how they impact our product, and ways we can mitigate that. I've pulled out the parts specific to our product, but the rest may be interesting. I would love feedback on things I may have missed. FWIW, it doesn't instill great confidence in SSL, but it isn't completely horrible. ------------------------ 1. It is possible to pretend to be…

How is Convergence different from the Perspectives add-on[1]? I ask because I honestly don't see any significant advantage to one over the other. [1] https://addons.mozilla.org/en-US/firefox/addon/perspectives/

You can also look at the video where he talks about Convergence.

http://www.youtube.com/watch?v=Z7Wl2FW2TcA (Start from 35m35s)

Re: Should All Web Traffic Be Encrypted?

#106
post #104

Earlier quoted context omitted.

If HTTP referrers never existed, the web would still be huge and would still be full of amazing content. Why should we care about retaining referrers? I think the only reason that people dislike the idea of losing them, is because they've got used to them being there. I don't particularly like the fact that sites which I click through to can see where I'm coming from, or what I was searching for, so I've installed a…

Referrer information allows website owners to see who is linking to their site. It's like a private, reverse form of tags

I agree that referrer information is useful to site owners. What you need to understand is that just because something is good for site owners, doesn't mean it's good for site visitors, or the web in general.

If you wanted to see who was linking to your site, and referrer headers didn't exist, you'd use a search engine. Hell, people would build dedicated search engines which alert you when somebody links to your site.

Referrers are good for identifying where a user came from, or what they were searching for when they land on your site. Well, sometimes they don't want you to have that information, and most of the time people are completely unaware that you're getting it.

Re: Should All Web Traffic Be Encrypted?

#107
post #55

One item that this (excellent) blog post does not adress is what to do about referer information which is generally not passed along when clicking on links on sites being browsed over SSL. In order to "get credit" for all of the traffic that they send everywhere twitter had to develop a fairly elaborate system of redirections (built into t.co) to make sure that clicks from twitter.com ended up being sent out to the r…

If HTTP referrers never existed, the web would still be huge and would still be full of amazing content. Why should we care about retaining referrers? I think the only reason that people dislike the idea of losing them, is because they've got used to them being there. I don't particularly like the fact that sites which I click through to can see where I'm coming from, or what I was searching for, so I've installed a…

> If HTTP referrers never existed, the web would still be huge and would still be full of amazing content.

While we're at it, let's get rid of User-Agent. No sarcasm intended, I'm serious. It only does bad things.

Re: Should All Web Traffic Be Encrypted?

#109
post #77

Earlier quoted context omitted.

I always expected this to do the same: If it doesn't, then what does it do? Default to http?

That's a relative URL. It would be equivalent to http://static4.scirra.net/static4.scirra.net/images/favicon....

Wow, this took forever to click. I have never written sites that spanned several servers like that. Thanks!

Re: Should All Web Traffic Be Encrypted?

#110

Earlier quoted context omitted.

Does rampant theft make theft any more acceptable?

No, but the fact that copyright infringement is not theft might.

Haha, looks like the MAFIAA war machine has been working pretty effectively that even HN readers are starting to believe it!
Post reply on HN